riddle-quiz-maker
Warn
Audited by Socket on Apr 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill is broadly coherent with its stated purpose, and the CLI comes from the official npm registry rather than an obviously rogue source. However, all authentication and Riddle Quiz Maker access are mediated through Membrane, a third-party platform, and the skill encourages dynamic action creation plus unpinned `@latest` CLI execution. This is not confirmed malware, but it carries meaningful trust and account-scope risk due to credential delegation, intermediary data flow, and the ability to perform live account actions.
Confidence: 84%Severity: 53%
Audit Metadata